Before giving an AI assistant access to internal documents, decide which documents deserve to answer a question. A shared folder can contain current procedures, abandoned drafts, personal notes, and customer-specific exceptions. Treating all of them as equally authoritative creates confusion even if search works perfectly.
This guide helps an owner or operations lead prepare a small, approved source collection. You will build a source register, resolve conflicts, and test who can retrieve what. Technical examples were checked on October 10, 2026; they illustrate design choices rather than a ready-made InstallAI connection.
1. Start with a set of real questions
Choose a narrow audience and write the questions it should be able to answer. An office team might need instructions for requesting supplies, finding an approved form, or checking the standard handoff process. Avoid beginning with “answer anything about the business.”
Find the source for each question. If the answer exists only in somebody's head, ask that person to document and approve it. AI should not fill a missing policy with a plausible practice borrowed from another business.
Record questions that should receive an abstention. “What discount can I promise this customer?” may require a manager's decision even if a general price list is available. An approved source can explain a process without authorizing an exception.
2. Build a small source register
For each document, record its title, stable link or file identifier, owner, intended audience, approval status, effective date, review date, and topics covered. Add the version used by the pilot. These fields make later answers traceable.
Use plain status labels such as approved, draft, superseded, and awaiting review. Define what each label means and who may change it. A recent modified date does not prove a document is approved; someone may have corrected a spelling mistake in an obsolete policy.
Choose one authoritative source for each rule. Where two documents disagree, have the responsible person resolve the conflict before both enter the pilot. Preserve the older document if your retention process requires it, but exclude it from ordinary current-policy answers.
3. Make the documents readable in context
Put important conditions beside the rule they qualify. If weekend support is available only under a particular service agreement, keep that limitation in the same section. An extracted paragraph that loses its heading or footnote can change the meaning.
Use descriptive headings, explicit dates, and consistent names for products or departments. Explain acronyms at first use. Keep customer-specific terms separate from general procedures, and label any example as an example.
Ask for a test showing what the system actually extracted. Inspect tables, scanned pages, and links. A document that opens correctly for a person may lose reading order or omit content when processed. A successful upload does not establish that the usable text is complete.
4. Check access at answer time
List the people or groups allowed to use each source. Then ask how the chosen system enforces those limits when a question is asked, including any copies held in a search index. Do not assume source-folder permissions automatically carry across every connector or custom system.
Microsoft's Azure AI Search documentation describes a security-filter pattern that excludes results using user or group identifiers. It also explains that those identifiers are strings, not authentication by themselves, and that the filter must be applied to every query. The surrounding application still needs a sound identity and authorization design. Azure AI Search security filters.
Test with an allowed user and a restricted user. The restricted test should cover answer text, quoted passages, source titles, and links. A helpful answer can still disclose confidential information before the reader clicks a document.
5. Plan for changes and removals
Name who updates the source register when a policy changes. Record how the system refreshes its copies and how someone confirms the new version is in use. Include a way to withdraw a source while a conflict is investigated.
Do not make revision history your only preservation plan. Google Drive documents that older uploaded-file revisions can be automatically purged unless kept under its revision controls; behavior depends on the file type. Verify the retention method for the files you actually use. Google Drive revision management.
Also test access revocation. Removing a person from the original folder should trigger a check of the search layer and any stored outputs. Ask the implementer what happens immediately, what may lag, and how the delay is detected.
Fictional example
Harbor Demo Studio is a fictional design company. Its team has two equipment-return guides. One says seven days; a newer approved guide says five. The operations lead marks the older guide superseded and approves the current one for the staff pilot. A customer contract with different terms stays in a separate restricted collection.
The test questions include the ordinary return period, an unsupported exception, and a request from someone outside the staff group. Success means the correct approved source is used or access is refused as designed. No accuracy percentage or customer benefit is claimed.
Readiness checklist
- Define the audience and supported questions.
- Assign an owner and status to every source.
- Resolve contradictory rules before indexing.
- Inspect extracted text and source references.
- Verify access for allowed and restricted users.
- Test a policy update and a permission removal.
- Name the person who handles unanswered questions.
Bring the source register and a handful of unanswered questions to InstallAI when discussing an internal knowledge workflow. They provide a clearer starting point than granting broad access and hoping the assistant finds the right material.
Sources checked
- Microsoft Azure AI Search security filter pattern Checked 2026-10-10
- Google Drive revision management Checked 2026-10-10